Cybercrime-as-a-Service: How Hacking is Becoming a Subscription Business

Cybercrime today looks a lot more like e-commerce. Let's explore how the democratization of hacking is lowering the barrier to entry and why your organization must evolve its defenses to keep up.

By Hirum KigothoTeam|Last updated: August 29, 2026|9 minutes read
cybersecurity
Cybercrime-as-a-Service: How Hacking is Becoming a Subscription Business
For decades, launching a serious cyberattack required a combination of technical knowledge, programming skills, patience, and access to specialized infrastructure. That barrier has steadily eroded. Today, someone with limited technical knowledge can gain access to capabilities that once required an experienced hacker. The result is a fundamental change in the cyberthreat landscape. The arrests of individuals linked to the Scattered Spider collective are an example. A 19-year-old was allegedly involved in $115 million in extortion targeting thousands of organizations after joining the cybercrime collective at the age of 15 or 16.

Why The Barrier to Entry Is Falling

Cybercrime-as-a-Service

One of the biggest forces behind this transformation is the rise of Cybercrime-as-a-Service (CaaS). The concept mirrors legitimate cloud and software businesses. Rather than building infrastructure from scratch, customers purchase access to an existing service. Criminal markets have adopted a similar model. This creates an environment in which cybercriminals can specialize while relying on other criminals for capabilities they do not possess. A technically inexperienced individual does not necessarily need to become proficient in penetration testing, reverse engineering, exploit development, or malware programming. They may only need enough knowledge to operate an existing platform.

Phishing Kits

Phishing provides one of the clearest examples of how cyberattacks have become easier to launch. Historically, creating a convincing phishing campaign required some combination of web development, hosting knowledge, email infrastructure, social engineering expertise, and an understanding of how authentication systems worked. Modern phishing kits can package much of that complexity into relatively accessible tools. Criminals can obtain templates that imitate familiar login pages, configure campaigns, collect credentials, and monitor victims through centralized interfaces. Some kits imitate widely used services and corporate authentication portals. Tycoon 2FA, currently considered one of the best phishing kits on the market, costs around $120 for 10 days of access through Telegram. It comes with documentation, customer-support channels, and regular feature updates.

Stolen Credentials Eliminate the Need to Break In

Another major factor is the enormous supply of stolen credentials available to criminals. Why spend time discovering how to compromise an organization when valid credentials may already exist? Infostealing malware has created a large underground supply of usernames, passwords, session information, cookies, and other authentication data. Criminals can trade this information, and specialized actors can use it to obtain access to corporate environments. This has helped create the market for initial access brokers. Initial-access brokers specialize in obtaining access to organizations and selling that access to other criminals. The buyer may have little interest in how the original compromise occurred. They simply want access. That separation between access acquisition and attack execution lowers the barrier to entry. A criminal who lacks the skills to compromise a corporate network may be able to purchase access and then use other services to conduct the next stages of an attack.

Automation Is Replacing Technical Labor

Automation is another reason the barrier to entry is falling. Cyberattacks involve many repetitive tasks: identifying potential targets, scanning systems, testing credentials, distributing messages, monitoring compromised machines, and processing stolen information. Automation allows criminals to perform these activities at a scale that would be impossible manually. A tool that automatically identifies potential targets can replace hours of reconnaissance. Automated credential testing can replace manual login attempts. Automated phishing infrastructure can handle large numbers of victims. Botnets can distribute malicious activity across thousands of compromised devices. Automation therefore changes the economics of cybercrime. Instead of asking how many targets one attacker can handle, criminals can ask how many targets their infrastructure can handle.

Artificial Intelligence

AI does not magically turn someone with no cybersecurity knowledge into an elite hacker. Advanced attacks still require expertise, operational security, infrastructure, and an understanding of complex environments. However, AI can reduce the amount of technical expertise required to carry out many individual tasks. An inexperienced attacker can use AI systems to create convincing social-engineering messages, translate the messages, and research potential targets. They can use AI to fill gaps in their knowledge and overcome technical obstacles they might otherwise struggle with. This lowers the knowledge threshold for cybercrime. This may lead to more people experimenting with offensive capabilities, while criminal marketplaces can develop new services to serve these less-skilled users. Group-IB reported that organizations worldwide suffered nearly $350 million in verifiable losses from deepfake fraud during the second quarter of 2025 alone. The falling technical barrier also reinforces the importance of social engineering. Technical vulnerabilities remain critically important, but criminals do not always need to exploit a sophisticated software flaw if they can convince an employee to surrender access. The human element can be considerably easier to manipulate than a hardened technical system. AI-generated text, voice cloning, fake profiles, and convincing websites can make these impersonation campaigns more persuasive. An example is when a company’s CFO transferred $25 million to an attacker-controlled account after participating in a Zoom call with individuals who appeared to be the company’s CEO and other executives. The attackers used deepfake technology to impersonate company leaders and persuade the CFO to complete the transaction.

Why Organizations Should Be Concerned

The democratization of cyberattacks changes the threat model for organizations. Today, the organization may face thousands of low-skilled attackers using automated tools simultaneously. Most of those attempts will fail. But attackers do not need a high success rate when the cost of attempting an attack is extremely low. If automation allows one criminal to target thousands of organizations, even a tiny success rate can produce meaningful results. This also increases the workload for defenders, who may need to investigate alerts, protect accounts, patch vulnerabilities, monitor endpoints, and respond to incidents individually.

What organizations can do

Defenders Must Also Democratize Security

If attackers benefit from automation and commoditized expertise, defenders need to do the same. Security teams should increasingly automate repetitive defensive tasks. The objective is not to automate security completely. It is to ensure that defenders can operate at a scale comparable to the threats they face. Defensive artificial intelligence can be particularly useful here, provided organizations maintain appropriate controls and human oversight. The same technologies that help attackers reduce technical barriers can help defenders reduce the workload created by increasingly automated attacks.

Train employees

Security awareness training also needs to evolve. Traditional training often teaches employees to identify obvious phishing emails. That is no longer enough. Employees may encounter highly personalized messages that reference real projects, coworkers, suppliers, job opportunities, invoices, or business relationships. Organizations therefore need security cultures built around verification rather than suspicion alone. Employees should have simple ways to verify unusual payment requests, credential requests, account changes, and sensitive instructions. The goal is not to expect employees to become cybersecurity experts. It is to create processes that prevent a single convincing interaction from becoming a catastrophic compromise.

Collective defense

One of the strongest defenses against the growing cybercrime-as-a-service ecosystem is collective defense, where organizations rapidly share threat intelligence, indicators of compromise, and emerging attack patterns rather than confronting threats in isolation. If security teams can identify a new phishing infrastructure, impersonation tactic, or credential-theft campaign early and distribute that intelligence across industries, other organizations can strengthen their defenses before they become targets.

Conclusion

Organizations may be putting themselves at greater risk by assuming that sophisticated attacks can only be carried out by highly skilled attackers. Security teams must now prepare for a much larger pool of threat actors whose access to automated tools, AI, and ready-made services gives them a far higher baseline level of capability. This does not mean technical hackers are disappearing. Sophisticated threat actors still develop advanced exploits, custom malware, and novel intrusion techniques. Instead, their expertise is increasingly being packaged into products and services that other criminals can consume.

Share this article

Frequently asked questions

Newsletter

Stay in the Loop.

Subscribe to our newsletter to receive the latest news, updates, and special offers directly in your inbox. Don't miss out!